Apache HTTP Server, Remote Code Execution, CVE-2021-42013 (Critical)

Listen to this Post

How the mentioned CVE works:

The CVE-2021-42013 vulnerability is a path traversal and remote code execution flaw in Apache HTTP Server versions 2.4.49 and 2.4.50. The vulnerability arises from an insufficient fix for CVE-2021-41773. The core issue lies in a path normalization error in the `ap_normalize_path()` function. When the `mod_cgi` module is enabled and the “require all denied” configuration is not set, an attacker can craft a malicious URL containing encoded path traversal sequences, such as `.%2e/` or %%32%65/. These sequences bypass the security checks implemented to address the previous CVE. A specially crafted request, for example, to /cgi-bin/..%%32%65/..%%32%65/..%%32%65/..%%32%65/bin/sh, can escape the document root. This allows the attacker to map the URL to files outside the expected directories. If the traversed path targets a CGI script, the server will execute the script with the privileges of the web server daemon, leading to arbitrary command execution on the underlying host.
Platform: Apache HTTP Server
Version: 2.4.49-50

Vulnerability : Path Traversal

Severity: Critical

date: 2021-10-07

Prediction: Patch Available

What Undercode Say:

curl -H "User-Agent: () { :; }; echo; /bin/cat /etc/passwd" http://vulnerable.host/cgi-bin/attack.cgi
nmap -sV --script http-vuln-cve2021-42013 <target>
grep -r "Require all denied" /etc/apache2/
// Example of a malicious request path
char exploit_path = "/cgi-bin/..%%32%65/..%%32%65/..%%32%65/..%%32%65/etc/passwd";

How Exploit:

Craft malicious URLs.

Bypass path normalization.

Execute system commands.

Protection from this CVE

Update to 2.4.51.

Implement “Require all denied”.

Disable unused CGI scripts.

Impact:

Remote Code Execution.

Information Disclosure.

System Compromise.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: nvd.nist.gov
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top